CISCO-CRYPTO-ACCELERATOR-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-CRYPTO-ACCELERATOR-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2005-03-08

Category: Cisco Devices, VPN and Security

Description: Monitors Cisco hardware cryptographic accelerator modules, providing statistics on encryption throughput, key operations, and acceleration offload.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-CRYPTO-ACCELERATOR-MIB?

CISCO-CRYPTO-ACCELERATOR-MIB is a Cisco MIB for monitoring the identity, status, activity, and faults of hardware cryptographic accelerator (CA) modules installed in Cisco security devices, such as VPN routers or firewalls with dedicated encryption offload hardware. It exposes discovery-related capability objects (ccaCapability), activity/statistics objects (ccaActivity, ccaGlobalStats, ccaProtocolActivity) tracking encryption throughput and protocol-specific offload activity, and a set of notifications for module lifecycle events. For hardware status monitoring, its notifications directly report physical hardware presence and health changes: ccaNotifCntlAcclInserted and ccaNotifCntlAcclRemoved signal hot-plug insertion/removal of a crypto accelerator card, while ccaNotifCntlAcclOperational and ccaNotifCntlAcclDisabled report the module transitioning to an operational or disabled fault state. The MIB's stated purpose explicitly ties its data to correlating crypto accelerator performance with the broader security services running on the device, implying a dependency on other Cisco security/VPN MIBs for full context, though it is otherwise a self-contained module. It is deployed on Cisco security appliances/routers equipped with hardware crypto acceleration cards handling IPsec/SSL encryption workloads. Engineers can download the CISCO-CRYPTO-ACCELERATOR-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-CRYPTO-ACCELERATOR-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco security appliances/routers with hardware crypto accelerator modules

Monitoring Examples

An administrator would monitor ccaGlobalStats and ccaProtocolActivity to track encryption throughput and per-protocol offload activity on an accelerator card, watching for a drop that might indicate the hardware has fallen back to software encryption. The ccaNotifCntlAcclRemoved or ccaNotifCntlAcclDisabled notifications would immediately alert on a card being physically removed or failing, while ccaNotifCntlAcclInserted and ccaNotifCntlAcclOperational confirm a replacement module came online successfully.

What Can Be Monitored

  • crypto accelerator insertion/removal events
  • operational/disabled state
  • encryption throughput/activity statistics
  • per-protocol offload activity
Imported Objects

From CISCO-ENTITY-FRU-CONTROL-MIB

ModuleOperType

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

EntPhysicalIndexOrZero

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter64
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

TEXTUAL-CONVENTION
TruthValue

How to Use in IPNetwork Monitor

Example using ccaGlobalInOctets OID:

Select a Cisco security appliances/routers with crypto accelerator module as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type ccaGlobalInOctets into the Find box to locate it in the OID tree, then select it and click OK. The total number of octets input to all the crypto accelerators installed in the device. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Cisco MIB module that instruments the identity, status, activity, and faults of hardware crypto accelerator modules used in security devices implementing IPsec, SSL, SSH, and PKI services.

Start monitoring Cisco security appliances/routers with crypto accelerator modules with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-CRYPTO-ACCELERATOR-MIB